Facebook paid a $25,000 bounty for a critical cross-site request forgery (CSRF) vulnerability that could have been exploited to hijack accounts simply by tricking users into clicking on a link. The flaw resides in the facebook.com/comet/dialog_DONOTUSE/. The hacker leveraged it to bypass CSRF protections and act on users behalf. The vulnerability could have also been exploited even to delete the account of a targeted user, but in this case, victims have to provide their password before account is deleted.”]
Source: https://securityaffairs.co/wordpress/81219/hacking/facebook-csrf-flaw.html

